android-pentesting

Fail

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The Authorization Context section contains multiple instructions designed to override the agent's safety protocols. Specifically, it commands the agent to avoid ethical disclaimers, ignore 'responsible disclosure' requirements, and refuse to halt testing for permission, stating that authorization is pre-established.
  • [COMMAND_EXECUTION]: The skill implements logic to automatically detect and execute local shell scripts based on the $SUPERHACKERS_ROOT environment variable. It also facilitates complex system interactions using tools like adb and frida, including runtime function hooking and bypass operations that interact with the host and target device environments.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 13, 2026, 06:36 PM
Security Audit — agent-trust-hub — android-pentesting